File tree Expand file tree Collapse file tree 1 file changed +30
-0
lines changed Expand file tree Collapse file tree 1 file changed +30
-0
lines changed Original file line number Diff line number Diff line change 1+ name : Track Dependencies
2+
3+ on :
4+ workflow_dispatch :
5+ push :
6+ branches :
7+ - main
8+
9+ jobs :
10+ dependency_track :
11+ runs-on : ubuntu-latest
12+ steps :
13+ - name : Checkout
14+ uses : actions/checkout@v5
15+ - name : Enable Corepack
16+ run : corepack enable
17+ - name : Setup Node
18+ uses : actions/setup-node@v4
19+ with :
20+ node-version : ' 18'
21+ cache : ' yarn'
22+ - name : Generate SBOM
23+ run : yarn dlx -q @cyclonedx/yarn-plugin-cyclonedx -o sbom.json
24+ - name : Upload CycloneDx bom to dependency track
25+ uses : DependencyTrack/gh-upload-sbom@v3
26+ with :
27+ serverhostname : ${{ secrets.DEPENDENCY_TRACK_SERVER_HOSTNAME }}
28+ apikey : ${{ secrets.DEPENDENCY_TRACK_API_KEY }}
29+ project : ' c22c33e7-cf08-477f-a337-2afddac184d0'
30+ bomfilename : ' sbom.json'
You can’t perform that action at this time.
0 commit comments